SB20250502279 - Resource management error in Linux kernel net driver
Published: May 2, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2022-49856)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the skb_headlen() function in drivers/net/tun.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/07d120aa33cc9d9115753d159f64d20c94458781
- https://git.kernel.org/stable/c/30b0263d0366ea63aa7cad0407dfd945cc348580
- https://git.kernel.org/stable/c/310f0855352ee4b2eb38855c99185c23e6e1496b
- https://git.kernel.org/stable/c/534762e261c84d43e5d56a780e40278b94c20540
- https://git.kernel.org/stable/c/9132fa043f96ac545254ab326db5c6fd47d54acb
- https://git.kernel.org/stable/c/999550c8cbb3fcb535f542d652fe1cb936839e5f
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.9